Current section

Files

Jump to
aws_erlang src aws_secrets_manager.erl
Raw

src/aws_secrets_manager.erl

%% WARNING: DO NOT EDIT, AUTO-GENERATED CODE!
%% See https://github.com/aws-beam/aws-codegen for more details.
%% @doc <fullname>AWS Secrets Manager API Reference</fullname>
%%
%% AWS Secrets Manager provides a service to enable you to store, manage, and
%% retrieve, secrets.
%%
%% This guide provides descriptions of the Secrets Manager API. For more
%% information about using this service, see the <a
%% href="https://docs.aws.amazon.com/secretsmanager/latest/userguide/introduction.html">AWS
%% Secrets Manager User Guide</a>.
%%
%% <b>API Version</b>
%%
%% This version of the Secrets Manager API Reference documents the Secrets
%% Manager API version 2017-10-17.
%%
%% <note> As an alternative to using the API, you can use one of the AWS
%% SDKs, which consist of libraries and sample code for various programming
%% languages and platforms such as Java, Ruby, .NET, iOS, and Android. The
%% SDKs provide a convenient way to create programmatic access to AWS Secrets
%% Manager. For example, the SDKs provide cryptographically signing requests,
%% managing errors, and retrying requests automatically. For more information
%% about the AWS SDKs, including downloading and installing them, see <a
%% href="http://aws.amazon.com/tools/">Tools for Amazon Web Services</a>.
%%
%% </note> We recommend you use the AWS SDKs to make programmatic API calls
%% to Secrets Manager. However, you also can use the Secrets Manager HTTP
%% Query API to make direct calls to the Secrets Manager web service. To
%% learn more about the Secrets Manager HTTP Query API, see <a
%% href="https://docs.aws.amazon.com/secretsmanager/latest/userguide/query-requests.html">Making
%% Query Requests</a> in the <i>AWS Secrets Manager User Guide</i>.
%%
%% Secrets Manager API supports GET and POST requests for all actions, and
%% doesn't require you to use GET for some actions and POST for others.
%% However, GET requests are subject to the limitation size of a URL.
%% Therefore, for operations that require larger sizes, use a POST request.
%%
%% <b>Support and Feedback for AWS Secrets Manager</b>
%%
%% We welcome your feedback. Send your comments to <a
%% href="mailto:awssecretsmanager-feedback@amazon.com">awssecretsmanager-feedback@amazon.com</a>,
%% or post your feedback and questions in the <a
%% href="http://forums.aws.amazon.com/forum.jspa?forumID=296">AWS Secrets
%% Manager Discussion Forum</a>. For more information about the AWS
%% Discussion Forums, see <a
%% href="http://forums.aws.amazon.com/help.jspa">Forums Help</a>.
%%
%% <b>How examples are presented</b>
%%
%% The JSON that AWS Secrets Manager expects as your request parameters and
%% the service returns as a response to HTTP query requests contain single,
%% long strings without line breaks or white space formatting. The JSON shown
%% in the examples displays the code formatted with both line breaks and
%% white space to improve readability. When example input parameters can also
%% cause long strings extending beyond the screen, you can insert line breaks
%% to enhance readability. You should always submit the input as a single
%% JSON text string.
%%
%% <b>Logging API Requests</b>
%%
%% AWS Secrets Manager supports AWS CloudTrail, a service that records AWS
%% API calls for your AWS account and delivers log files to an Amazon S3
%% bucket. By using information that's collected by AWS CloudTrail, you can
%% determine the requests successfully made to Secrets Manager, who made the
%% request, when it was made, and so on. For more about AWS Secrets Manager
%% and support for AWS CloudTrail, see <a
%% href="http://docs.aws.amazon.com/secretsmanager/latest/userguide/monitoring.html#monitoring_cloudtrail">Logging
%% AWS Secrets Manager Events with AWS CloudTrail</a> in the <i>AWS Secrets
%% Manager User Guide</i>. To learn more about CloudTrail, including enabling
%% it and find your log files, see the <a
%% href="https://docs.aws.amazon.com/awscloudtrail/latest/userguide/what_is_cloud_trail_top_level.html">AWS
%% CloudTrail User Guide</a>.
-module(aws_secrets_manager).
-export([cancel_rotate_secret/2,
cancel_rotate_secret/3,
create_secret/2,
create_secret/3,
delete_resource_policy/2,
delete_resource_policy/3,
delete_secret/2,
delete_secret/3,
describe_secret/2,
describe_secret/3,
get_random_password/2,
get_random_password/3,
get_resource_policy/2,
get_resource_policy/3,
get_secret_value/2,
get_secret_value/3,
list_secret_version_ids/2,
list_secret_version_ids/3,
list_secrets/2,
list_secrets/3,
put_resource_policy/2,
put_resource_policy/3,
put_secret_value/2,
put_secret_value/3,
restore_secret/2,
restore_secret/3,
rotate_secret/2,
rotate_secret/3,
tag_resource/2,
tag_resource/3,
untag_resource/2,
untag_resource/3,
update_secret/2,
update_secret/3,
update_secret_version_stage/2,
update_secret_version_stage/3,
validate_resource_policy/2,
validate_resource_policy/3]).
-include_lib("hackney/include/hackney_lib.hrl").
%%====================================================================
%% API
%%====================================================================
%% @doc Disables automatic scheduled rotation and cancels the rotation of a
%% secret if currently in progress.
%%
%% To re-enable scheduled rotation, call <a>RotateSecret</a> with
%% <code>AutomaticallyRotateAfterDays</code> set to a value greater than 0.
%% This immediately rotates your secret and then enables the automatic
%% schedule.
%%
%% <note> If you cancel a rotation while in progress, it can leave the
%% <code>VersionStage</code> labels in an unexpected state. Depending on the
%% step of the rotation in progress, you might need to remove the staging
%% label <code>AWSPENDING</code> from the partially created version,
%% specified by the <code>VersionId</code> response value. You should also
%% evaluate the partially rotated new version to see if it should be deleted,
%% which you can do by removing all staging labels from the new version
%% <code>VersionStage</code> field.
%%
%% </note> To successfully start a rotation, the staging label
%% <code>AWSPENDING</code> must be in one of the following states:
%%
%% <ul> <li> Not attached to any version at all
%%
%% </li> <li> Attached to the same version as the staging label
%% <code>AWSCURRENT</code>
%%
%% </li> </ul> If the staging label <code>AWSPENDING</code> attached to a
%% different version than the version with <code>AWSCURRENT</code> then the
%% attempt to rotate fails.
%%
%% <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:CancelRotateSecret
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To configure rotation for a secret or to manually trigger a
%% rotation, use <a>RotateSecret</a>.
%%
%% </li> <li> To get the rotation configuration details for a secret, use
%% <a>DescribeSecret</a>.
%%
%% </li> <li> To list all of the currently available secrets, use
%% <a>ListSecrets</a>.
%%
%% </li> <li> To list all of the versions currently associated with a secret,
%% use <a>ListSecretVersionIds</a>.
%%
%% </li> </ul>
cancel_rotate_secret(Client, Input)
when is_map(Client), is_map(Input) ->
cancel_rotate_secret(Client, Input, []).
cancel_rotate_secret(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"CancelRotateSecret">>, Input, Options).
%% @doc Creates a new secret. A secret in Secrets Manager consists of both
%% the protected secret data and the important information needed to manage
%% the secret.
%%
%% Secrets Manager stores the encrypted secret data in one of a collection of
%% "versions" associated with the secret. Each version contains a copy of the
%% encrypted secret data. Each version is associated with one or more
%% "staging labels" that identify where the version is in the rotation cycle.
%% The <code>SecretVersionsToStages</code> field of the secret contains the
%% mapping of staging labels to the active versions of the secret. Versions
%% without a staging label are considered deprecated and not included in the
%% list.
%%
%% You provide the secret data to be encrypted by putting text in either the
%% <code>SecretString</code> parameter or binary data in the
%% <code>SecretBinary</code> parameter, but not both. If you include
%% <code>SecretString</code> or <code>SecretBinary</code> then Secrets
%% Manager also creates an initial secret version and automatically attaches
%% the staging label <code>AWSCURRENT</code> to the new version.
%%
%% <note> <ul> <li> If you call an operation to encrypt or decrypt the
%% <code>SecretString</code> or <code>SecretBinary</code> for a secret in the
%% same account as the calling user and that secret doesn't specify a AWS KMS
%% encryption key, Secrets Manager uses the account's default AWS managed
%% customer master key (CMK) with the alias <code>aws/secretsmanager</code>.
%% If this key doesn't already exist in your account then Secrets Manager
%% creates it for you automatically. All users and roles in the same AWS
%% account automatically have access to use the default CMK. Note that if an
%% Secrets Manager API call results in AWS creating the account's AWS-managed
%% CMK, it can result in a one-time significant delay in returning the
%% result.
%%
%% </li> <li> If the secret resides in a different AWS account from the
%% credentials calling an API that requires encryption or decryption of the
%% secret value then you must create and use a custom AWS KMS CMK because you
%% can't access the default CMK for the account using credentials from a
%% different AWS account. Store the ARN of the CMK in the secret when you
%% create the secret or when you update it by including it in the
%% <code>KMSKeyId</code>. If you call an API that must encrypt or decrypt
%% <code>SecretString</code> or <code>SecretBinary</code> using credentials
%% from a different account then the AWS KMS key policy must grant
%% cross-account access to that other account's user or role for both the
%% kms:GenerateDataKey and kms:Decrypt operations.
%%
%% </li> </ul> </note>
%%
%% <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:CreateSecret
%%
%% </li> <li> kms:GenerateDataKey - needed only if you use a customer-managed
%% AWS KMS key to encrypt the secret. You do not need this permission to use
%% the account default AWS managed CMK for Secrets Manager.
%%
%% </li> <li> kms:Decrypt - needed only if you use a customer-managed AWS KMS
%% key to encrypt the secret. You do not need this permission to use the
%% account default AWS managed CMK for Secrets Manager.
%%
%% </li> <li> secretsmanager:TagResource - needed only if you include the
%% <code>Tags</code> parameter.
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To delete a secret, use <a>DeleteSecret</a>.
%%
%% </li> <li> To modify an existing secret, use <a>UpdateSecret</a>.
%%
%% </li> <li> To create a new version of a secret, use <a>PutSecretValue</a>.
%%
%% </li> <li> To retrieve the encrypted secure string and secure binary
%% values, use <a>GetSecretValue</a>.
%%
%% </li> <li> To retrieve all other details for a secret, use
%% <a>DescribeSecret</a>. This does not include the encrypted secure string
%% and secure binary values.
%%
%% </li> <li> To retrieve the list of secret versions associated with the
%% current secret, use <a>DescribeSecret</a> and examine the
%% <code>SecretVersionsToStages</code> response value.
%%
%% </li> </ul>
create_secret(Client, Input)
when is_map(Client), is_map(Input) ->
create_secret(Client, Input, []).
create_secret(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"CreateSecret">>, Input, Options).
%% @doc Deletes the resource-based permission policy attached to the secret.
%%
%% <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:DeleteResourcePolicy
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To attach a resource policy to a secret, use
%% <a>PutResourcePolicy</a>.
%%
%% </li> <li> To retrieve the current resource-based policy that's attached
%% to a secret, use <a>GetResourcePolicy</a>.
%%
%% </li> <li> To list all of the currently available secrets, use
%% <a>ListSecrets</a>.
%%
%% </li> </ul>
delete_resource_policy(Client, Input)
when is_map(Client), is_map(Input) ->
delete_resource_policy(Client, Input, []).
delete_resource_policy(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"DeleteResourcePolicy">>, Input, Options).
%% @doc Deletes an entire secret and all of its versions. You can optionally
%% include a recovery window during which you can restore the secret. If you
%% don't specify a recovery window value, the operation defaults to 30 days.
%% Secrets Manager attaches a <code>DeletionDate</code> stamp to the secret
%% that specifies the end of the recovery window. At the end of the recovery
%% window, Secrets Manager deletes the secret permanently.
%%
%% At any time before recovery window ends, you can use <a>RestoreSecret</a>
%% to remove the <code>DeletionDate</code> and cancel the deletion of the
%% secret.
%%
%% You cannot access the encrypted secret information in any secret that is
%% scheduled for deletion. If you need to access that information, you must
%% cancel the deletion with <a>RestoreSecret</a> and then retrieve the
%% information.
%%
%% <note> <ul> <li> There is no explicit operation to delete a version of a
%% secret. Instead, remove all staging labels from the
%% <code>VersionStage</code> field of a version. That marks the version as
%% deprecated and allows Secrets Manager to delete it as needed. Versions
%% that do not have any staging labels do not show up in
%% <a>ListSecretVersionIds</a> unless you specify
%% <code>IncludeDeprecated</code>.
%%
%% </li> <li> The permanent secret deletion at the end of the waiting period
%% is performed as a background task with low priority. There is no guarantee
%% of a specific time after the recovery window for the actual delete
%% operation to occur.
%%
%% </li> </ul> </note> <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:DeleteSecret
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To create a secret, use <a>CreateSecret</a>.
%%
%% </li> <li> To cancel deletion of a version of a secret before the recovery
%% window has expired, use <a>RestoreSecret</a>.
%%
%% </li> </ul>
delete_secret(Client, Input)
when is_map(Client), is_map(Input) ->
delete_secret(Client, Input, []).
delete_secret(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"DeleteSecret">>, Input, Options).
%% @doc Retrieves the details of a secret. It does not include the encrypted
%% fields. Secrets Manager only returns fields populated with a value in the
%% response.
%%
%% <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:DescribeSecret
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To create a secret, use <a>CreateSecret</a>.
%%
%% </li> <li> To modify a secret, use <a>UpdateSecret</a>.
%%
%% </li> <li> To retrieve the encrypted secret information in a version of
%% the secret, use <a>GetSecretValue</a>.
%%
%% </li> <li> To list all of the secrets in the AWS account, use
%% <a>ListSecrets</a>.
%%
%% </li> </ul>
describe_secret(Client, Input)
when is_map(Client), is_map(Input) ->
describe_secret(Client, Input, []).
describe_secret(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"DescribeSecret">>, Input, Options).
%% @doc Generates a random password of the specified complexity. This
%% operation is intended for use in the Lambda rotation function. Per best
%% practice, we recommend that you specify the maximum length and include
%% every character type that the system you are generating a password for can
%% support.
%%
%% <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:GetRandomPassword
%%
%% </li> </ul>
get_random_password(Client, Input)
when is_map(Client), is_map(Input) ->
get_random_password(Client, Input, []).
get_random_password(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"GetRandomPassword">>, Input, Options).
%% @doc Retrieves the JSON text of the resource-based policy document
%% attached to the specified secret. The JSON request string input and
%% response output displays formatted code with white space and line breaks
%% for better readability. Submit your input as a single line JSON string.
%%
%% <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:GetResourcePolicy
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To attach a resource policy to a secret, use
%% <a>PutResourcePolicy</a>.
%%
%% </li> <li> To delete the resource-based policy attached to a secret, use
%% <a>DeleteResourcePolicy</a>.
%%
%% </li> <li> To list all of the currently available secrets, use
%% <a>ListSecrets</a>.
%%
%% </li> </ul>
get_resource_policy(Client, Input)
when is_map(Client), is_map(Input) ->
get_resource_policy(Client, Input, []).
get_resource_policy(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"GetResourcePolicy">>, Input, Options).
%% @doc Retrieves the contents of the encrypted fields
%% <code>SecretString</code> or <code>SecretBinary</code> from the specified
%% version of a secret, whichever contains content.
%%
%% <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:GetSecretValue
%%
%% </li> <li> kms:Decrypt - required only if you use a customer-managed AWS
%% KMS key to encrypt the secret. You do not need this permission to use the
%% account's default AWS managed CMK for Secrets Manager.
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To create a new version of the secret with different encrypted
%% information, use <a>PutSecretValue</a>.
%%
%% </li> <li> To retrieve the non-encrypted details for the secret, use
%% <a>DescribeSecret</a>.
%%
%% </li> </ul>
get_secret_value(Client, Input)
when is_map(Client), is_map(Input) ->
get_secret_value(Client, Input, []).
get_secret_value(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"GetSecretValue">>, Input, Options).
%% @doc Lists all of the versions attached to the specified secret. The
%% output does not include the <code>SecretString</code> or
%% <code>SecretBinary</code> fields. By default, the list includes only
%% versions that have at least one staging label in <code>VersionStage</code>
%% attached.
%%
%% <note> Always check the <code>NextToken</code> response parameter when
%% calling any of the <code>List*</code> operations. These operations can
%% occasionally return an empty or shorter than expected list of results even
%% when there more results become available. When this happens, the
%% <code>NextToken</code> response parameter contains a value to pass to the
%% next call to the same API to request the next part of the list.
%%
%% </note> <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:ListSecretVersionIds
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To list the secrets in an account, use <a>ListSecrets</a>.
%%
%% </li> </ul>
list_secret_version_ids(Client, Input)
when is_map(Client), is_map(Input) ->
list_secret_version_ids(Client, Input, []).
list_secret_version_ids(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"ListSecretVersionIds">>, Input, Options).
%% @doc Lists all of the secrets that are stored by Secrets Manager in the
%% AWS account. To list the versions currently stored for a specific secret,
%% use <a>ListSecretVersionIds</a>. The encrypted fields
%% <code>SecretString</code> and <code>SecretBinary</code> are not included
%% in the output. To get that information, call the <a>GetSecretValue</a>
%% operation.
%%
%% <note> Always check the <code>NextToken</code> response parameter when
%% calling any of the <code>List*</code> operations. These operations can
%% occasionally return an empty or shorter than expected list of results even
%% when there more results become available. When this happens, the
%% <code>NextToken</code> response parameter contains a value to pass to the
%% next call to the same API to request the next part of the list.
%%
%% </note> <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:ListSecrets
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To list the versions attached to a secret, use
%% <a>ListSecretVersionIds</a>.
%%
%% </li> </ul>
list_secrets(Client, Input)
when is_map(Client), is_map(Input) ->
list_secrets(Client, Input, []).
list_secrets(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"ListSecrets">>, Input, Options).
%% @doc Attaches the contents of the specified resource-based permission
%% policy to a secret. A resource-based policy is optional. Alternatively,
%% you can use IAM identity-based policies that specify the secret's Amazon
%% Resource Name (ARN) in the policy statement's <code>Resources</code>
%% element. You can also use a combination of both identity-based and
%% resource-based policies. The affected users and roles receive the
%% permissions that are permitted by all of the relevant policies. For more
%% information, see <a
%% href="http://docs.aws.amazon.com/secretsmanager/latest/userguide/auth-and-access_resource-based-policies.html">Using
%% Resource-Based Policies for AWS Secrets Manager</a>. For the complete
%% description of the AWS policy syntax and grammar, see <a
%% href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies.html">IAM
%% JSON Policy Reference</a> in the <i>IAM User Guide</i>.
%%
%% <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:PutResourcePolicy
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To retrieve the resource policy attached to a secret, use
%% <a>GetResourcePolicy</a>.
%%
%% </li> <li> To delete the resource-based policy that's attached to a
%% secret, use <a>DeleteResourcePolicy</a>.
%%
%% </li> <li> To list all of the currently available secrets, use
%% <a>ListSecrets</a>.
%%
%% </li> </ul>
put_resource_policy(Client, Input)
when is_map(Client), is_map(Input) ->
put_resource_policy(Client, Input, []).
put_resource_policy(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"PutResourcePolicy">>, Input, Options).
%% @doc Stores a new encrypted secret value in the specified secret. To do
%% this, the operation creates a new version and attaches it to the secret.
%% The version can contain a new <code>SecretString</code> value or a new
%% <code>SecretBinary</code> value. You can also specify the staging labels
%% that are initially attached to the new version.
%%
%% <note> The Secrets Manager console uses only the <code>SecretString</code>
%% field. To add binary data to a secret with the <code>SecretBinary</code>
%% field you must use the AWS CLI or one of the AWS SDKs.
%%
%% </note> <ul> <li> If this operation creates the first version for the
%% secret then Secrets Manager automatically attaches the staging label
%% <code>AWSCURRENT</code> to the new version.
%%
%% </li> <li> If another version of this secret already exists, then this
%% operation does not automatically move any staging labels other than those
%% that you explicitly specify in the <code>VersionStages</code> parameter.
%%
%% </li> <li> If this operation moves the staging label
%% <code>AWSCURRENT</code> from another version to this version (because you
%% included it in the <code>StagingLabels</code> parameter) then Secrets
%% Manager also automatically moves the staging label
%% <code>AWSPREVIOUS</code> to the version that <code>AWSCURRENT</code> was
%% removed from.
%%
%% </li> <li> This operation is idempotent. If a version with a
%% <code>VersionId</code> with the same value as the
%% <code>ClientRequestToken</code> parameter already exists and you specify
%% the same secret data, the operation succeeds but does nothing. However, if
%% the secret data is different, then the operation fails because you cannot
%% modify an existing version; you can only create new ones.
%%
%% </li> </ul> <note> <ul> <li> If you call an operation to encrypt or
%% decrypt the <code>SecretString</code> or <code>SecretBinary</code> for a
%% secret in the same account as the calling user and that secret doesn't
%% specify a AWS KMS encryption key, Secrets Manager uses the account's
%% default AWS managed customer master key (CMK) with the alias
%% <code>aws/secretsmanager</code>. If this key doesn't already exist in your
%% account then Secrets Manager creates it for you automatically. All users
%% and roles in the same AWS account automatically have access to use the
%% default CMK. Note that if an Secrets Manager API call results in AWS
%% creating the account's AWS-managed CMK, it can result in a one-time
%% significant delay in returning the result.
%%
%% </li> <li> If the secret resides in a different AWS account from the
%% credentials calling an API that requires encryption or decryption of the
%% secret value then you must create and use a custom AWS KMS CMK because you
%% can't access the default CMK for the account using credentials from a
%% different AWS account. Store the ARN of the CMK in the secret when you
%% create the secret or when you update it by including it in the
%% <code>KMSKeyId</code>. If you call an API that must encrypt or decrypt
%% <code>SecretString</code> or <code>SecretBinary</code> using credentials
%% from a different account then the AWS KMS key policy must grant
%% cross-account access to that other account's user or role for both the
%% kms:GenerateDataKey and kms:Decrypt operations.
%%
%% </li> </ul> </note> <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:PutSecretValue
%%
%% </li> <li> kms:GenerateDataKey - needed only if you use a customer-managed
%% AWS KMS key to encrypt the secret. You do not need this permission to use
%% the account's default AWS managed CMK for Secrets Manager.
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To retrieve the encrypted value you store in the version of a
%% secret, use <a>GetSecretValue</a>.
%%
%% </li> <li> To create a secret, use <a>CreateSecret</a>.
%%
%% </li> <li> To get the details for a secret, use <a>DescribeSecret</a>.
%%
%% </li> <li> To list the versions attached to a secret, use
%% <a>ListSecretVersionIds</a>.
%%
%% </li> </ul>
put_secret_value(Client, Input)
when is_map(Client), is_map(Input) ->
put_secret_value(Client, Input, []).
put_secret_value(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"PutSecretValue">>, Input, Options).
%% @doc Cancels the scheduled deletion of a secret by removing the
%% <code>DeletedDate</code> time stamp. This makes the secret accessible to
%% query once again.
%%
%% <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:RestoreSecret
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To delete a secret, use <a>DeleteSecret</a>.
%%
%% </li> </ul>
restore_secret(Client, Input)
when is_map(Client), is_map(Input) ->
restore_secret(Client, Input, []).
restore_secret(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"RestoreSecret">>, Input, Options).
%% @doc Configures and starts the asynchronous process of rotating this
%% secret. If you include the configuration parameters, the operation sets
%% those values for the secret and then immediately starts a rotation. If you
%% do not include the configuration parameters, the operation starts a
%% rotation with the values already stored in the secret. After the rotation
%% completes, the protected service and its clients all use the new version
%% of the secret.
%%
%% This required configuration information includes the ARN of an AWS Lambda
%% function and the time between scheduled rotations. The Lambda rotation
%% function creates a new version of the secret and creates or updates the
%% credentials on the protected service to match. After testing the new
%% credentials, the function marks the new secret with the staging label
%% <code>AWSCURRENT</code> so that your clients all immediately begin to use
%% the new version. For more information about rotating secrets and how to
%% configure a Lambda function to rotate the secrets for your protected
%% service, see <a
%% href="https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotating-secrets.html">Rotating
%% Secrets in AWS Secrets Manager</a> in the <i>AWS Secrets Manager User
%% Guide</i>.
%%
%% Secrets Manager schedules the next rotation when the previous one
%% completes. Secrets Manager schedules the date by adding the rotation
%% interval (number of days) to the actual date of the last rotation. The
%% service chooses the hour within that 24-hour date window randomly. The
%% minute is also chosen somewhat randomly, but weighted towards the top of
%% the hour and influenced by a variety of factors that help distribute load.
%%
%% The rotation function must end with the versions of the secret in one of
%% two states:
%%
%% <ul> <li> The <code>AWSPENDING</code> and <code>AWSCURRENT</code> staging
%% labels are attached to the same version of the secret, or
%%
%% </li> <li> The <code>AWSPENDING</code> staging label is not attached to
%% any version of the secret.
%%
%% </li> </ul> If the <code>AWSPENDING</code> staging label is present but
%% not attached to the same version as <code>AWSCURRENT</code> then any later
%% invocation of <code>RotateSecret</code> assumes that a previous rotation
%% request is still in progress and returns an error.
%%
%% <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:RotateSecret
%%
%% </li> <li> lambda:InvokeFunction (on the function specified in the
%% secret's metadata)
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To list the secrets in your account, use <a>ListSecrets</a>.
%%
%% </li> <li> To get the details for a version of a secret, use
%% <a>DescribeSecret</a>.
%%
%% </li> <li> To create a new version of a secret, use <a>CreateSecret</a>.
%%
%% </li> <li> To attach staging labels to or remove staging labels from a
%% version of a secret, use <a>UpdateSecretVersionStage</a>.
%%
%% </li> </ul>
rotate_secret(Client, Input)
when is_map(Client), is_map(Input) ->
rotate_secret(Client, Input, []).
rotate_secret(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"RotateSecret">>, Input, Options).
%% @doc Attaches one or more tags, each consisting of a key name and a value,
%% to the specified secret. Tags are part of the secret's overall metadata,
%% and are not associated with any specific version of the secret. This
%% operation only appends tags to the existing list of tags. To remove tags,
%% you must use <a>UntagResource</a>.
%%
%% The following basic restrictions apply to tags:
%%
%% <ul> <li> Maximum number of tags per secret—50
%%
%% </li> <li> Maximum key length—127 Unicode characters in UTF-8
%%
%% </li> <li> Maximum value length—255 Unicode characters in UTF-8
%%
%% </li> <li> Tag keys and values are case sensitive.
%%
%% </li> <li> Do not use the <code>aws:</code> prefix in your tag names or
%% values because AWS reserves it for AWS use. You can't edit or delete tag
%% names or values with this prefix. Tags with this prefix do not count
%% against your tags per secret limit.
%%
%% </li> <li> If you use your tagging schema across multiple services and
%% resources, remember other services might have restrictions on allowed
%% characters. Generally allowed characters: letters, spaces, and numbers
%% representable in UTF-8, plus the following special characters: + - = . _ :
%% / @.
%%
%% </li> </ul> <important> If you use tags as part of your security strategy,
%% then adding or removing a tag can change permissions. If successfully
%% completing this operation would result in you losing your permissions for
%% this secret, then the operation is blocked and returns an Access Denied
%% error.
%%
%% </important> <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:TagResource
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To remove one or more tags from the collection attached to a
%% secret, use <a>UntagResource</a>.
%%
%% </li> <li> To view the list of tags attached to a secret, use
%% <a>DescribeSecret</a>.
%%
%% </li> </ul>
tag_resource(Client, Input)
when is_map(Client), is_map(Input) ->
tag_resource(Client, Input, []).
tag_resource(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"TagResource">>, Input, Options).
%% @doc Removes one or more tags from the specified secret.
%%
%% This operation is idempotent. If a requested tag is not attached to the
%% secret, no error is returned and the secret metadata is unchanged.
%%
%% <important> If you use tags as part of your security strategy, then
%% removing a tag can change permissions. If successfully completing this
%% operation would result in you losing your permissions for this secret,
%% then the operation is blocked and returns an Access Denied error.
%%
%% </important> <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:UntagResource
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To add one or more tags to the collection attached to a secret,
%% use <a>TagResource</a>.
%%
%% </li> <li> To view the list of tags attached to a secret, use
%% <a>DescribeSecret</a>.
%%
%% </li> </ul>
untag_resource(Client, Input)
when is_map(Client), is_map(Input) ->
untag_resource(Client, Input, []).
untag_resource(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"UntagResource">>, Input, Options).
%% @doc Modifies many of the details of the specified secret. If you include
%% a <code>ClientRequestToken</code> and <i>either</i>
%% <code>SecretString</code> or <code>SecretBinary</code> then it also
%% creates a new version attached to the secret.
%%
%% To modify the rotation configuration of a secret, use <a>RotateSecret</a>
%% instead.
%%
%% <note> The Secrets Manager console uses only the <code>SecretString</code>
%% parameter and therefore limits you to encrypting and storing only a text
%% string. To encrypt and store binary data as part of the version of a
%% secret, you must use either the AWS CLI or one of the AWS SDKs.
%%
%% </note> <ul> <li> If a version with a <code>VersionId</code> with the same
%% value as the <code>ClientRequestToken</code> parameter already exists, the
%% operation results in an error. You cannot modify an existing version, you
%% can only create a new version.
%%
%% </li> <li> If you include <code>SecretString</code> or
%% <code>SecretBinary</code> to create a new secret version, Secrets Manager
%% automatically attaches the staging label <code>AWSCURRENT</code> to the
%% new version.
%%
%% </li> </ul> <note> <ul> <li> If you call an operation to encrypt or
%% decrypt the <code>SecretString</code> or <code>SecretBinary</code> for a
%% secret in the same account as the calling user and that secret doesn't
%% specify a AWS KMS encryption key, Secrets Manager uses the account's
%% default AWS managed customer master key (CMK) with the alias
%% <code>aws/secretsmanager</code>. If this key doesn't already exist in your
%% account then Secrets Manager creates it for you automatically. All users
%% and roles in the same AWS account automatically have access to use the
%% default CMK. Note that if an Secrets Manager API call results in AWS
%% creating the account's AWS-managed CMK, it can result in a one-time
%% significant delay in returning the result.
%%
%% </li> <li> If the secret resides in a different AWS account from the
%% credentials calling an API that requires encryption or decryption of the
%% secret value then you must create and use a custom AWS KMS CMK because you
%% can't access the default CMK for the account using credentials from a
%% different AWS account. Store the ARN of the CMK in the secret when you
%% create the secret or when you update it by including it in the
%% <code>KMSKeyId</code>. If you call an API that must encrypt or decrypt
%% <code>SecretString</code> or <code>SecretBinary</code> using credentials
%% from a different account then the AWS KMS key policy must grant
%% cross-account access to that other account's user or role for both the
%% kms:GenerateDataKey and kms:Decrypt operations.
%%
%% </li> </ul> </note> <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:UpdateSecret
%%
%% </li> <li> kms:GenerateDataKey - needed only if you use a custom AWS KMS
%% key to encrypt the secret. You do not need this permission to use the
%% account's AWS managed CMK for Secrets Manager.
%%
%% </li> <li> kms:Decrypt - needed only if you use a custom AWS KMS key to
%% encrypt the secret. You do not need this permission to use the account's
%% AWS managed CMK for Secrets Manager.
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To create a new secret, use <a>CreateSecret</a>.
%%
%% </li> <li> To add only a new version to an existing secret, use
%% <a>PutSecretValue</a>.
%%
%% </li> <li> To get the details for a secret, use <a>DescribeSecret</a>.
%%
%% </li> <li> To list the versions contained in a secret, use
%% <a>ListSecretVersionIds</a>.
%%
%% </li> </ul>
update_secret(Client, Input)
when is_map(Client), is_map(Input) ->
update_secret(Client, Input, []).
update_secret(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"UpdateSecret">>, Input, Options).
%% @doc Modifies the staging labels attached to a version of a secret.
%% Staging labels are used to track a version as it progresses through the
%% secret rotation process. You can attach a staging label to only one
%% version of a secret at a time. If a staging label to be added is already
%% attached to another version, then it is moved--removed from the other
%% version first and then attached to this one. For more information about
%% staging labels, see <a
%% href="https://docs.aws.amazon.com/secretsmanager/latest/userguide/terms-concepts.html#term_staging-label">Staging
%% Labels</a> in the <i>AWS Secrets Manager User Guide</i>.
%%
%% The staging labels that you specify in the <code>VersionStage</code>
%% parameter are added to the existing list of staging labels--they don't
%% replace it.
%%
%% You can move the <code>AWSCURRENT</code> staging label to this version by
%% including it in this call.
%%
%% <note> Whenever you move <code>AWSCURRENT</code>, Secrets Manager
%% automatically moves the label <code>AWSPREVIOUS</code> to the version that
%% <code>AWSCURRENT</code> was removed from.
%%
%% </note> If this action results in the last label being removed from a
%% version, then the version is considered to be 'deprecated' and can be
%% deleted by Secrets Manager.
%%
%% <b>Minimum permissions</b>
%%
%% To run this command, you must have the following permissions:
%%
%% <ul> <li> secretsmanager:UpdateSecretVersionStage
%%
%% </li> </ul> <b>Related operations</b>
%%
%% <ul> <li> To get the list of staging labels that are currently associated
%% with a version of a secret, use <code> <a>DescribeSecret</a> </code> and
%% examine the <code>SecretVersionsToStages</code> response value.
%%
%% </li> </ul>
update_secret_version_stage(Client, Input)
when is_map(Client), is_map(Input) ->
update_secret_version_stage(Client, Input, []).
update_secret_version_stage(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"UpdateSecretVersionStage">>, Input, Options).
%% @doc Validates the JSON text of the resource-based policy document
%% attached to the specified secret. The JSON request string input and
%% response output displays formatted code with white space and line breaks
%% for better readability. Submit your input as a single line JSON string. A
%% resource-based policy is optional.
validate_resource_policy(Client, Input)
when is_map(Client), is_map(Input) ->
validate_resource_policy(Client, Input, []).
validate_resource_policy(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"ValidateResourcePolicy">>, Input, Options).
%%====================================================================
%% Internal functions
%%====================================================================
-spec request(aws_client:aws_client(), binary(), map(), list()) ->
{ok, Result, {integer(), list(), hackney:client()}} |
{error, Error, {integer(), list(), hackney:client()}} |
{error, term()} when
Result :: map() | undefined,
Error :: {binary(), binary()}.
request(Client, Action, Input, Options) ->
Client1 = Client#{service => <<"secretsmanager">>},
Host = get_host(<<"secretsmanager">>, Client1),
URL = get_url(Host, Client1),
Headers = [
{<<"Host">>, Host},
{<<"Content-Type">>, <<"application/x-amz-json-1.1">>},
{<<"X-Amz-Target">>, << <<"secretsmanager.">>/binary, Action/binary>>}
],
Payload = jsx:encode(Input),
SignedHeaders = aws_request:sign_request(Client1, <<"POST">>, URL, Headers, Payload),
Response = hackney:request(post, URL, SignedHeaders, Payload, Options),
handle_response(Response).
handle_response({ok, 200, ResponseHeaders, Client}) ->
case hackney:body(Client) of
{ok, <<>>} ->
{ok, undefined, {200, ResponseHeaders, Client}};
{ok, Body} ->
Result = jsx:decode(Body, [return_maps]),
{ok, Result, {200, ResponseHeaders, Client}}
end;
handle_response({ok, StatusCode, ResponseHeaders, Client}) ->
{ok, Body} = hackney:body(Client),
Error = jsx:decode(Body, [return_maps]),
Exception = maps:get(<<"__type">>, Error, undefined),
Reason = maps:get(<<"message">>, Error, undefined),
{error, {Exception, Reason}, {StatusCode, ResponseHeaders, Client}};
handle_response({error, Reason}) ->
{error, Reason}.
get_host(_EndpointPrefix, #{region := <<"local">>}) ->
<<"localhost">>;
get_host(EndpointPrefix, #{region := Region, endpoint := Endpoint}) ->
aws_util:binary_join([EndpointPrefix, <<".">>, Region, <<".">>, Endpoint], <<"">>).
get_url(Host, Client) ->
Proto = maps:get(proto, Client),
Port = maps:get(port, Client),
aws_util:binary_join([Proto, <<"://">>, Host, <<":">>, Port, <<"/">>], <<"">>).